OperationsData & AnalyticsAI & Agent WorkflowsOpen accessPublished 3 Oct 2026
Assemble a third-party AI due-diligence package for an external AI provider or model: map submitted evidence to the required governance domains (viability, transparency, data governance, subprocessors, concentration, security, testing, contractual rights, resilience, exit), check coverage and freshness against the versioned rubric, tie every finding to a bundled evidence item, compute a deterministic residual-risk rating, and draft the pack with a RECOMMENDED disposition. Use when a third-party-risk, procurement, or AI-governance reviewer must assess or onboard an external AI/GenAI vendor, check evidence completeness (SOC 2, model card, DPA, eval results), or prepare a di…